1. can i use free ca for my set-up? if yes, where can i create and how can i install the ca?
2. do i need to install ca for every server?
3. in the future if i buy ca, where can i get one? how many, etc?

As Saleesh mentioned you can use an Internal CA for your internal certificates, then 2 Public CA Certificates for your Edge and Reverse Proxy. No you do not need to install a CA on every server, you install your CA on 1 server, which will provide certificates
for all computers/users in your AD domain. you cant buy a CA, you can buy a certificate to use to publish your Lync deployment on the internet. I suggest using GoDaddy UCC Certificates and they are cheep, just under $100. but rememeber you will need 2 of them!

If this post answered your question, Mark As Answer If this post was helpful, Vote as Helpful http://lyncme.blogspot.com

As Saleesh mentioned you can use an Internal CA for your internal certificates, then 2 Public CA Certificates for your Edge and Reverse Proxy. No you do not need to install a CA on every server, you install your CA on 1 server, which will provide certificates
for all computers/users in your AD domain. you cant buy a CA, you can buy a certificate to use to publish your Lync deployment on the internet. I suggest using GoDaddy UCC Certificates and they are cheep, just under $100. but rememeber you will need 2 of them!

If this post answered your question, Mark As Answer If this post was helpful, Vote as Helpful http://lyncme.blogspot.com

Microsoft is conducting an online survey to understand your opinion of the Technet Web site. If you choose to participate, the online survey will be presented to you when you leave the Technet Web site.